US2011243322A1PendingUtilityA1

Security in telecommunications systems

Assignee: VODAFONE PLCPriority: Jan 17, 2008Filed: Jan 19, 2009Published: Oct 6, 2011
Est. expiryJan 17, 2028(~1.4 yrs left)· nominal 20-yr term from priority
H04W 84/042H04L 63/1475H04L 63/30H04W 84/12H04L 63/0428H04W 12/037H04W 12/122H04W 12/033
33
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Security of communications between a mobile terminal 1 and a cellular network node (base station 3 ) is enhanced. A communication session transmitted on a first traffic channel ‘0’ is encrypted using a key ‘KA’. The security is enhanced by causing the communication channel to change to a second communication channel ‘7’ after a predetermined time, preferably very quickly after establishing the key. In one embodiment the communication channel then changes to a third communication channel ‘25’ after a predetermined time. In another embodiment the communication session is encrypted using a second key ‘KB’after causing the communication channel to change to the second communication channel ‘7’.

Claims

exact text as granted — not AI-modified
1 . A method of providing security in communications between a device and a telecommunications network node, the method including encrypting a communication session transmitted on a first communication channel using a key, and causing the communication session to change to a second communication channel at a predetermined time. 
     
     
         2 . The method of  claim 1 , including causing the communication session to change to a third communication channel at a predetermined time. 
     
     
         3 . The method of  claim 1 , including encrypting the communication session using a second key at a predetermined time after causing the communication session to change to the second communication channel and at a predetermined time. 
     
     
         4 . A method of providing security in communications between a device and a telecommunications network node, the method including;
 encrypting a communication session transmitted on a first channel using a key,   performing a first change to the communication session carrier by causing the communication session to change to a second communication channel at a predetermined time, and   performing a second change to the communication session carrier at a predetermined time.   
     
     
         5 . The method of  claim 4 , wherein the second change to the carrier causes the communication session to change to a third communication channel at a predetermined time. 
     
     
         6 . The method of  claim 4 , wherein the second change to the carrier includes encrypting the communication session using a second key at a predetermined time after causing the communication session to change to the second communication channel and at a predetermined time. 
     
     
         7 . The method of  claim 1 , wherein frequency hopping is performed during the communication session over a wide range of frequencies. 
     
     
         8 . The method of  claim 1 , including modifying conventional plaintext messages sent during the communication session. 
     
     
         9 . The method of  claim 1 , wherein the communications network is a cellular telecommunications network and the device is a mobile device that communicates with the cellular telecommunications network node wirelessly. 
     
     
         10 . The method of  claim 9 , wherein the communication network is a GSM cellular telecommunications network. 
     
     
         11 . The network of  claim 9 , wherein the communication is encrypted according to an A5/1 algorithm. 
     
     
         12 . The method of  claim 1 , wherein the respective communication channels have different frequencies and/or time slots. 
     
     
         13 . The method of  claim 4 , wherein the key is obtainable by an attacker after an initial phase of analyzing a channel carrying the communication session, and wherein the second change to the carrier is performed before the initial phase of analyzing the channel is completed. 
     
     
         14 . The method of  claim 4 , wherein the key is obtainable by an attacker after cryptanalytic processing of a channel carrying the communication session, and wherein the second change to the carrier is performed before the cryptanalytic processing of the channel can be completed. 
     
     
         15 . The method of  claim 4 , wherein the key is obtainable by an attacker after cryptanalytic processing of a channel carrying the communication session, and wherein the predetermined time at which the second change to the carrier is performed within the minimum time that the cryptanalytic process is expected to take. 
     
     
         16 . A telecommunications system including:
 a device,   a telecommunications network node,   means for encrypting a communication session between the device and the node transmitted on a first channel using a key,   means for performing a first change to the communication session carrier by causing the communication session to change to a second communication channel at a predetermined time, and   means for performing a second change to the communication session carrier at a predetermined time.   
     
     
         17 . The system of  claim 16 , wherein the second change to the carrier causes the communication session to change the third communication channel at a predetermined time. 
     
     
         18 . The system of  claim 16 , wherein the second change to the carrier includes encrypting the communication session using a second key at a predetermined time after causing the communication session to change to the second communication channel and at a predetermined time. 
     
     
         19 . A base station for transmitting communications relating to a communication session to a device on a first channel, the communication session being encrypted using a key, the base station being adapted to perform a first change to the communication session carrier by causing the communication session to change to a second channel at a predetermined time, and being adapted to perform a second change to the communication session carrier at a predetermined time. 
     
     
         20 . The base station of  claim 19 , wherein the second change to the carrier causes the communication session to change the third communication channel at a predetermined time. 
     
     
         21 . The base station of  claim 19 , wherein the second change to the carrier includes encrypting the communication using a second key at a predetermined time after causing the communication session to change to the second communication channel and at a predetermined time. 
     
     
         22 . A method for improving the security in GSM networks, specially to GSM networks implementing the A5/1 ciphering protocol the method comprising:
 (A) a first method for the reduction of predictable information, in order to reduce the amount of known information available to the hacker, thus increasing the number of messages/calls time recorded needed by the hacker in order to decipher A5/1 key;   (B) a second method for call tracking;   wherein the effect of the second method depends on the amount of messages needed to crack the A5/1 ciphering protocol;   and wherein the first method makes the amount of messages as big as possible, hence there is a multiplicative effect on the combination of said first and second method.   
     
     
         23 . The method of  claim 22  wherein said first method further comprises:
 a method of randomization of dummy bits sent in any message in the GSM air interface; and 
 a method for increasing the optional information to be sent by the mobile to the network. 
 
     
     
         24 . The method of  claim 22  wherein said second method further comprises:
 a method for signaling handover, where right after the first ciphered message (ciphering mode complete), while still in the signaling phase, the user will be reallocated to another signaling channel; 
 a method for periodic traffic reallocations, which is possible through forced periodic intra-cell handovers. 
 
     
     
         25 . The method of  claim 22  wherein during the signaling handover the user will be reallocated to another signaling channel, either on the same or another cell while the uncertainty will increase if it is done to another cell. 
     
     
         26 . A telecommunication system including:
 a device,   a telecommunications network node,   means for the reduction of predictable information in the signaling traffic at the beginning of a call, further comprising:
 means for the randomization of the dummy bits included in the call; and 
 means for increasing the optional information in the call; 
   means for call tracking, further comprising:
 means for the signaling handover; and 
 means for periodic traffic reallocations.

Join the waitlist — get patent alerts

Track US2011243322A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.